Riskware detection policy rules help you to identify objects by suspicious file types and mark them as riskware. The Email Security - Server appliance receives a list of updated riskware policy rules when the system checks for new security content from the DTI Cloud. Both the rule ID and rule name are unique. Analysis is performed against all matched rules.
When you enable at least one matched policy rule on the Email Security - Server appliance, the appliance generates a riskware alert on a non-malicious submission. No further analysis is performed. The submission status for a riskware alert of a policy rule is marked as Custom Riskware in the output of the show submission id command.
You can also enable a matched custom policy rule to block an email based on riskware detection on the Email Security - Server appliance. For details about how to block an email based on a matched policy rule, see Enabling or disabling blocking files based on riskware detection custom policy rules using the Web UI or Enabling or disabling blocking files based on riskware detection custom policy rules using the CLI.
You can mark as riskware or block emails that contain attachments with specific file extensions. For details about how to block an email or generate an alert based on a matched file extension, see Enabling or disabling blocking files based on riskware detection custom policy rules using the Web UI or Enabling or disabling blocking files based on riskware detection custom policy rules using the CLI.
This section contains the following information:
The following table describes some of the riskware detection custom policy rules that can trigger a riskware alert. You can see the full list of riskware policy rules in the Web UI in Settings > Riskware Policy.
Riskware policy rule | Trigger condition |
|---|---|
65000 Jar Files Delivered Via Email Attachment Or Link | Jar files are delivered through email attachments or links. |
65001 Encrypted MS Office Document | Microsoft Office files in emails are encrypted. |
65002 PDF, HWP or MS Office Files With Network Activity | Microsoft Office files are used for network activity. |
65003 Executable Delivered via Email Attachment or Link within Email Body | Email attachments have suspicious executable files (such as PEEXE or PEDLL). |
65004 Scripts Delivered via Email | Email messages include scripts. |
65005 Low Confidence Custom Yara Rule Weights 0-50 | Custom YARA rules applied reach total weights between 0 and 50. See About YARA rules |
65006 High Confidence Custom Yara Rule Weights 51-99 | Custom YARA rules applied reach total weights between 51 and 99. See About YARA rules. |
65007 MS Office Document With Embedded Object | Microsoft Office files have embedded objects. |
65008 MS Office Document With Macro Activity | Microsoft Office files have macro activity. |
65009 Non Executable file Connecting to Non-Standard High Port | Non-executable files that connect to ports above 1024. |
65010 MS Office Document with Network Activity and Embedded Object or Macro | Microsoft Office files have network activity and embedded objects or macros. |
65011 Uncommon File Types Delivered Via Email BAT, CPL, LNK, COM, CMD, MHT, PIF, PUB, HLP, HTA, ISO | Emails have file attachments with any of the following file types: BAT, CPL, LNK, COM, CMD, MHT, PIF, PUB, HLP, HTA, ISO |
65012 MS Office Document With Macro Activity Dropping a exe file | Microsoft Office files have macro activity that write executable files. |
65013 Password From Web Forms Sent as Plaintext Http_Request | Email Web forms have passwords that are sent as plain-text HTTP requests. |
65014 Low Confidence Custom Email Header Yara Rule Weights 0-50 Matched | Custom YARA rules for EHDR files with total weight between 0 and 50. See About YARA rules. |
65015 High Confidence Custom Email Header Yara Rule Weights 51-99 Matched | Custom YARA rules for EHDR files with total weight between 51 and 99. See About YARA rules. |
65016 Email HTML Attachment Accessing Shortened URL Link | Emails contain URLs that have been shortened. See Embedded URL analysis. |
65017 Email with MS Access DB Attached | Email messages have Microsoft Access database attachments. |
65020 MS Office document running flash events | Any MS office document runs flash events |
65021 MS Office document with password protection macro | Any MS office document having password protection macros |
65022 Login page sent as email attachment or URL | Login page sent as email attachment or URL |
65023 Password protected archives | Archives with password protection |
65024 Uncommon filetype observed | Uncommon filetype observed in email attachment |
65025 File with disagreeing extension and MagicBytes | Files have invalid extension |
65027 High Confidence Email Impersonation | Email impersonation detection has determined that email impersonation is very likely. See Impersonation detection rules. |
65028 Low Confidence Email Impersonation | Email impersonation detection has determined that email impersonation is somewhat likely. See Impersonation detection rules. |
65030 Encrypted PDF document | Email contains encrypted PDF document |
65033 HTML Redirector Sent as Email Attachment | Email messages send an attachment with HTML code for redirection. |
65034 Low Confidence Malware Guard on EX | Malware Guard scores a binary file as riskware rather than malware. See Malware guard integration. |
65036 Matching Recipient and Message ID Domains | An email message header has matching domains for recipient and message ID. |
65037 Suspicious DAA Archive Delivered via Email | Email messages have suspicious Direct Access Archive file attachments. |
65038 Supply Chain Impersonation | Email feature extraction and Trellix Advanced URL Detection Engine (FAUDE) detect supply chain impersonation. See Enabling a riskware rule for supply chain impersonation using the Web UI. |
65041 Attacker Abused Legit Tool | Detection of productivity or other legitimate tools that are known to be leveraged as threat actor tactics, techniques, and procedures (TTPs). |
65043 Firewall/AV Discovery via WMI | Detection of Firewall or AV via WMI |
65044 Potentially Corrupt Windows PE File | Detection of corrupt windows file attachments |
65045 Office Document with Template Link | Email messages have office document with template link |
65046 MS Excel Formula Macro Sheet | Email messages have MS Excel formula macro sheet |
65047 MS Office Document with Embedded SWF | Any MS office document having embedded SWF |
65048 MSIL Reflective Loader File Through Emails | Email messages having MSIL reflective loader file |
65049 File NSIS Delivered Through Emails | File NSIS Delivered Through Emails |
65050 File ONENOTE With Embedded Object Delivered Through Emails | Email messages having file ONENOTE With embedded object |
65052 Potential ZipBomb | Email messages having potential zipBomb |
65053 CryptoJS Used n JavaScript | Crypto JS Used in JavaScript |
65054 MS Excel Formula Python Script | Email messages having MS excel formula python script |
65055 QR Code Observed | Email messages having QR code |
65056 JScript Deobfuscation Functions Observed in File | Email messages having JScript deobfuscation functions in attached file |
65057 Branchlock Obfuscated in File | Email messages having branchlock obfuscated in attached file |
65059 Mitre Multiple Tactics Observed in Executable File | Email messages having Mitre multiple tactics observed in executable file |
65060 RDP Files Delivered via Email | Email messages having RDP files |
65061 MSI File with Custom Action Scripts | Email messages having MSI file with custom action scripts |
65062 SVG File Delivered via Email | Email messages having SVG file |
65063 Password Protection HWP Document | Email messages having password protection HWP document |
65064 Packer Obfuscated MSIL | Email messages having packer obfuscated MSIL |
65065 ClickOnce Deployment Manifest | Email messages having ClickOnce deployment manifest |
65066 Password Extraction Failed | Failure of password extraction |
65067 ClickOnce Deployment Manifest Process | Email messages having ClickOnce deployment manifest process |
65068 Double Extension FileName | File name having double extension |
65069 PDF Embedded Script | Email messages having policy PDF embedded script |
65070 Theme File Delivered via Email | File with theme extension delivered via email |
65071 URLFeature CloudFlare Recaptcha Reasons | URL is CloudFlare and Recaptcha based on AUDE |
Note
Riskware detection custom policy rule configuration is disabled by default.